Taiwan Semiconductor Manufacturing Company's computer virus outbreak began on the evening of Friday 3 August 2018 and, before the weekend was out, had reached fab tools and computer systems at three plants: Fab 12 in the Hsinchu Science Park, Fab 15 in the Central Taiwan Science Park at Taichung, and Fab 14 in the south, at Tainan. What the machines did was not dramatic in the way ransomware usually is. The Windows computers that sit beside each piece of fab equipment running its automation interface crashed and rebooted, and crashed and rebooted again; the automated materials handling systems stopped moving wafers between them. TSMC said afterwards that data integrity and confidential information had not been compromised. Nothing, in the end, had been aimed at TSMC at all.
TSMC's own account, published on 5 August, contains no villain. The company blamed "misoperation during the software installation process for a new tool" — a new machine had arrived, software had been installed on it, and it had gone onto the corporate network before anyone isolated it and confirmed it was clean. The next day the chief executive, C.C. Wei, identified the malware as a variant of WannaCry and told reporters the incident was purely the company's own negligence, with no hacking behaviour involved. The worm had been loose since the three days in May 2017 this archive covers separately; the Microsoft patch closing the flaw it used had shipped in March of that year. Attribution, for once, pointed inward.
The figures came in that same 5 August statement, and they repay reading. About 80 per cent of the affected tools had been recovered by two o'clock that afternoon, Taiwan time; full recovery was expected the next day. TSMC put the impact on third-quarter revenue at about 3 per cent and on gross margin at about one percentage point, said the delayed shipments would be recovered in the fourth quarter, and kept the high single-digit annual growth forecast issued on 19 July. On 6 August Wei revised the revenue figure down again, to less than 2 per cent. The $255 million that attached itself to the story was press arithmetic against TSMC's own guidance — never a company number, and a measure of deferred revenue, not of what the incident cost.
The reason the trade press counted more than ten thousand unpatched Windows 7 machines inside those fabs is the part of the story that outlived it. A fab tool is qualified as a single unit, controller included, and changing anything on that controller means both downtime and the supplier's agreement — roughly what Wei said when asked why the machines had not been patched. The vendor's validated image therefore ages in place, inside a building where an hour of unscheduled stoppage is counted in millions of dollars. TSMC promised a more automated anti-virus procedure for new tool installations, recovered fully within three days, and did not revise its annual guidance. Eight years on, this remains the clearest answer to why an unpatched machine sits on a factory floor.
Reddit's 2007 backup
Reddit disclosed on 1 August 2018 that an attacker had been inside parts of its infrastructure six weeks earlier, and the company was careful about the sequence: the intrusion ran from 14 to 18 June, and Reddit found it on 19 June. That leaves roughly six weeks between discovery and the public post. The attacker had taken over a handful of employee accounts by intercepting the text messages carrying their second-factor codes, and held read access rather than write access — enough to reach a complete copy of a 2007 database backup covering the site from its 2005 launch through May 2007, holding usernames, salted and hashed passwords, email addresses and the content of that era. Separately, the attacker read logs of the email digests Reddit sent between 3 and 17 June 2018, which tied current usernames to current email addresses. Reddit moved its staff onto token-based authentication and said, in as many words, that SMS-based authentication was not as secure as it had hoped. It is the month that conclusion went mainstream.
The replica and the rebuttal
DEF CON 26 ran in Las Vegas from 9 to 12 August 2018, and the most widely reported thing that happened there was done by children. At r00tz Asylum, the conference's programme for young people, participants were handed replicas of the election-night reporting websites run by secretaries of state in thirteen battleground states, Florida among them, and invited to change what they said, using basic SQL injection. Two eleven-year-olds altered the tallies on the Florida replica, one in about ten minutes and the other in roughly fifteen. Then the qualifications arrived, and they matter. The National Association of Secretaries of State said the exercise used an environment that in no way replicated real state systems, and that such sites publish preliminary, unofficial results rather than counting votes. ProPublica went further on 24 August: the replicas were simplified mock-ups with vulnerabilities deliberately planted, the children had cheat sheets, and adults walked them through. What survives all of it is that the unofficial number is the one the public sees first.
Two days at Cosmos Bank
The FBI's alert went out on Friday 10 August 2018, warning banks of an imminent "unlimited operations" ATM cash-out. Cosmos Co-operative Bank of Pune, founded in 1906, was hit the next day. Over some seven hours on Saturday 11 August, cloned non-EMV debit cards were presented at cash machines in 28 countries while a malicious proxy switch, stood up beside the bank's own ATM switch server, intercepted the authorisation requests and answered them itself, approving withdrawals against balances the core banking system never saw. Securonix later counted roughly 12,000 international Visa and about 2,800 domestic RuPay transactions on some 450 cloned cards, worth ₹80.5 crore, ₹78 crore of it abroad. On Monday 13 August, three fraudulent SWIFT MT103 messages moved a further ₹13.92 crore to ALM Trading Limited at Hang Seng Bank in Hong Kong, bringing the total to ₹94.42 crore, about $13.5 million.
The chairman, Milind Kale, said the core banking system had not been touched, that no depositor had lost money and that the bank would absorb the loss; early reports put the country count at 21 before it settled at 28. Researchers thought the tradecraft resembled the Lazarus Group's, and a US-CERT alert that October described the same payment-switch technique at banks in Africa and Asia since 2016 — but it did not name Cosmos, and Indian investigators said they could not tie the case to any named group. Pune police arrested at least eighteen, almost all mules, and in April 2023 a magistrate convicted eleven — nine to four years, two to three. About ₹5.72 crore was recovered with Hong Kong's help. Whoever wrote the malware has never been identified, and the CERT-In six-hour rule was four years away.
Tensor cores reach the desktop
NVIDIA unveiled the Turing architecture at SIGGRAPH on 13 August 2018, first in the workstation Quadro RTX boards and then, at Gamescom on 20 August, in the consumer GeForce RTX 20-series. The coverage went to real-time ray tracing; the more consequential silicon was the tensor cores beside it, and the first mass-market feature built on them, Deep Learning Super Sampling, which reconstructed frames rendered at lower resolution using a trained network. Inference hardware had reached a card sold for playing games, on a design line that would underwrite the next decade of model training. Nature Medicine carried DeepMind's work with Moorfields Eye Hospital on that same 13 August: a system reading three-dimensional OCT retinal scans that recommended referral across more than fifty sight-threatening conditions as accurately as expert clinicians. Later that month OpenAI Five lost both its exhibition matches at The International in Vancouver, on 22 and 23 August — a result it reversed the following April, with eight times the training compute, against the reigning world champions.
Eight per cent and an open investigation
Symantec reported its fiscal first quarter on 2 August 2018 and announced a restructuring cutting up to about 8 per cent of its global workforce. The internal accounting investigation disclosed in May, opened after a former employee raised concerns about the company's public disclosures and non-GAAP reporting, was described only as ongoing; the shares fell sharply. The audit committee concluded it on 24 September, deferring $12 million of a $13 million transaction and citing behaviour inconsistent with the company's code of conduct, and the following August the enterprise business went to Broadcom for $10.7 billion, the consumer remainder renamed NortonLifeLock. On that same 2 August, Cisco agreed to buy Duo Security for $2.35 billion — a bet on checking the user and the device before granting access rather than on inspecting files. The rest of the month went on patching: Foreshadow, disclosed on 14 August, read data out of Intel's SGX enclaves, and on 27 August a researcher published a working Windows Task Scheduler privilege-escalation exploit with no patch available, malware using it within days.
⏳ Time capsule — August 2018
- Apple closed above a trillion-dollar market value on 2 August, the first American public company to do so.
- NASA launched the Parker Solar Probe on 12 August, on a mission to fly closer to the Sun than any spacecraft before it; its closest approach came in December 2024.
- The Morandi motorway bridge in Genoa collapsed on 14 August, killing 43 people.
- Aretha Franklin died at her home in Detroit on 16 August, aged 76.
The month nobody was attacked
August 2018's cover story has no attacker in it, which is exactly why it kept being cited. A worm released fifteen months earlier was still circulating, met an unpatched machine carried through the door by the company's own logistics, and stopped a factory — the same shape as Norsk Hydro's return to pen and paper in March 2019 and Colonial Pipeline's precautionary shutdown in May 2021, where in each case the software that failed and the thing that stopped were not the same system. The structural answer took years to arrive: SEMI E187, the first cybersecurity specification written for fab equipment itself, covering operating-system support, network security, endpoint protection and monitoring, was not published until January 2022.
The month's other threads all arrived somewhere. Reddit's intercepted text messages made SMS the weakest surviving second factor, and the industry spent the following years replacing it with hardware tokens and then with passkeys. On 20 August, Check Point described a new hand-operated ransomware called Ryuk, built on the older Hermes code and already past $640,000 in a fortnight — the opening of the targeted extortion economy that reaches hospitals by March 2020. And the attribution question left hanging over Cosmos Bank stayed open, though the following month American prosecutors named a North Korean programmer in a criminal complaint that ran through Sony and Bangladesh Bank without ever mentioning Pune. The Vault continues backwards from here.